Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Sun Solaris AnswerBook2 Multiple Cross-Site Scripting Vulnerabilities

An exploit is not required.

The following proof of concepts are available:

For the cross-site scripting issue in the Answerbook2 search function:
http://www.example.com/ab2/Help_C/@Ab2HelpSearch?scope=HELP&DwebQuery=%3Cscript%3Ealert%28%22hello%22%
29%3C%2Fscript%3E&Search=+Search+

For the admin interface 'View Log Files' function:
http://www.example.com/ab2/@Ab2Admin?command=view_access







 

Privacy Statement
Copyright 2008, SecurityFocus